Security1 publisher2 min readPublished
Even at their lowest rate in months, high-risk prompts hit 86% of GenAI-using organizations
Check Point's August 2026 telemetry puts flagged prompts at 1 in 43, the lowest rate in several months, while per-user prompt volume rose to 106 and weekly attacks, phishing and ransomware all climbed.
The Watch · Security desk

What happened
- Check Point recorded the lowest high-risk GenAI prompt rate in several months for August 2026, at one flagged prompt in every 43 sent from enterprise networks.
- Even at that rate, 86% of organizations using GenAI regularly still saw high-risk prompt activity during the month.
- Healthcare and Medical had the highest prompt exposure rate at 1 in 25 prompts, ahead of Software and Business Services at 1 in 28.
- Ransomware reports came to 1,042 for the month, up 8% on July and close to double the year-earlier count, while phishing rose to 1 in every 112 emails.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure With seven GenAI applications per organization on average, controls scoped to the one sanctioned assistant watch a minority of the prompt traffic that carries the data.
- constraint Rate alone is not a reliable control-effectiveness metric. A falling percentage on rising volume can still mean more sensitive prompts leaving the building each month.
- decision Healthcare data owners face the sharpest prioritisation call, because their per-user exposure count runs about 72% above the cross-industry figure at the same usage level.
- precedent Prompt exposure now belongs on the same monthly reporting line as phishing rate rather than in an AI pilot review, since the quietest month on the metric still touched most GenAI-using organizations.
The average user sent 106 prompts in August, up from 95 in July [1]. At August's flagged rate, that is about 2.5 data-exposure prompts per user for the month [1], or roughly 2,465 across a thousand seats [2]. In Healthcare and Medical, the highest-exposure sector, the same user accounts for about 4.2 [3], some 72% above the cross-industry figure [12].
A rate at a multi-month low [2] still leaves open whether exposure actually shrank. Per-user volume rose 11.6% between July and August [4], so the count of high-risk prompts per user fell only if the rate dropped by more than about 10% [5]. Check Point published August's rate and not July's [10], which leaves the product of rate and volume, the number a data-loss program actually cares about, unreconstructable from the release. The volume side is moving fast: 78 prompts per user in June against 106 in August is a 36% rise in two months [1][9].
That traffic is also split across tools. Check Point counts seven GenAI applications per organization on average and calls the spread a governance gap [12]. Its own framing puts the risk in what employees type rather than in whether the tool was sanctioned, and adds indirect prompt injection through externally sourced content to the same surface [13].
The rest of the board moved in one direction. The four-month attack series runs from 2,055 weekly attacks per organization in May to 2,422 in August [8], 367 more per week, an 18% climb [6]. August's 1,042 ransomware reports at 8% above July implies roughly 965 in July [7][7]. The phishing shift from 1 in 128 to 1 in 112 emails is about a 14% increase in the rate [6][8]. Education stayed the most-targeted sector at 5,354 weekly attacks, up 28% year over year [9]. The sharpest sector move was Hospitality, Travel and Recreation, up 56% to 3,056 and into third place ahead of Telecommunications [10]; Check Point attributes that to peak summer travel pressure, which the report offers as a suggestion rather than a finding [11]. Europe posted the highest regional growth at 28% [14].
The August figures come without a definition of a high-risk prompt, a sample size, or one incident traced to a leaked prompt [11]. The series trends consistently as month-over-month data from a single vendor's install base, but it offers no evidence of data actually lost, because the 86% figure counts organizations that produced flagged prompts [3], a population distinct from organizations that lost anything. A company wanting the number Check Point does not supply has to multiply its own monthly prompt volume by its own flag rate.
What to watch
- Whether Check Point publishes September's high-risk prompt rate next to prompt volume, which would settle if per-user exposure rose or fell.
- Whether the 56% rise in Hospitality, Travel and Recreation attacks holds once the summer travel season ends.
- Any incident report tracing confirmed data loss to a prompt, which the August figures do not contain.